CVE-2025-40573
MEDIUMDescription
A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices are vulnerable to path traversal attacks. This could allow a privileged local attacker to restore backups that are outside the backup folder.
Is your site exposed to CVE-2025-40573?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| siemens | scalance_lpe9403_firmware |
| siemens | scalance_lpe9403 |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2025-40573? +
How severe is CVE-2025-40573? +
What products are affected by CVE-2025-40573? +
How do I check if I'm vulnerable to CVE-2025-40573? +
Related Vulnerabilities
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a directory traversal vulnerability in Configuration Management that could allow …
DIAView (v4.2.0 and prior) - Directory Traversal Information Disclosure Vulnerability
A vulnerability was discovered in the firmware builds up to 8.2.1.0820 in certain Poly devices. The firmware flaw does not …
A Path Traversal vulnerability in the tftpsync/add and tftpsync/delete scripts allows a remote attacker on an adjacent network to write …
Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall performs rule …
The default TCL Camera application exposes a provider vulnerable to path traversal vulnerability. Malicious application can supply malicious URI path …